I still think that the best approach to password requirements was the one used at Nortel. They ran a password hash cracking algorithm continuously on the PW database, and when they cracked yours you had to change it. Other than that there were no complexity requirements or mandatory change intervals. If you had a good complex password you got to keep it for a long time, and if you set '12345', 1 minute later you'd have to change it.